Short Name |
HTTP:STC:IE:ANTIXSS-INFO-DISC |
---|---|
Severity |
Medium |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Microsoft Internet Explorer Anti-XSS Library Information Disclosure |
Release Date |
2012/01/09 |
Update Number |
2061 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to circumvent Microsoft's Anti-XSS Library. A successful attack could bypass the Cross Site Script (XSS) filter and allow unintended sensitive information disclosure to malicious third parties, possibly including user names, passwords, addresses, phone numbers, credit card numbers, or government identification numbers.
Microsoft Anti-Cross Site Scripting (AntiXSS) Library is prone to a security-bypass vulnerability that affects the sanitization module. An attacker can exploit this vulnerability to bypass the filter and conduct cross-site scripting attacks. Successful exploits may allow attackers to execute arbitrary script code and steal cookie-based authentication credentials. Microsoft Anti-Cross Site Scripting Library 3.x and 4.0 are vulnerable.